CVE-2022-0770 Information
Jun 07, 2022
cve
Description
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files and write debug data such as user’s cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues an attacker could gain access to a logged in admin cookies by making them open a malicious link or page
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/49abe79c-ab1c-4dbf-824c-8daaac7e079d
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: